vulnti.work

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achiev…

High CVSS 7.4
CVECVE-2026-15563
First seen2026-08-11 10:15 UTC
Disclosed2026-08-11 09:17 UTC
Last updated2026-08-11 10:15 UTC
Channel statusauto

Summary

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD